Re: 2 questions
Roland Zink <roland@zinks.de> Mon, 30 March 2015 14:01 UTC
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1F4D81ACEEB for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 30 Mar 2015 07:01:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.113
X-Spam-Level:
X-Spam-Status: No, score=-5.113 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JZm7mY9oJZA3 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 30 Mar 2015 07:01:27 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D5171ACEED for <httpbisa-archive-bis2Juki@lists.ietf.org>; Mon, 30 Mar 2015 07:01:27 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YcaCe-00050Y-Tq for ietf-http-wg-dist@listhub.w3.org; Mon, 30 Mar 2015 13:58:08 +0000
Resent-Date: Mon, 30 Mar 2015 13:58:08 +0000
Resent-Message-Id: <E1YcaCe-00050Y-Tq@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <roland@zinks.de>) id 1YcaCX-0004z1-2t for ietf-http-wg@listhub.w3.org; Mon, 30 Mar 2015 13:58:01 +0000
Received: from mo4-p00-ob.smtp.rzone.de ([81.169.146.220]) by lisa.w3.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.72) (envelope-from <roland@zinks.de>) id 1YcaCO-0003ok-OD for ietf-http-wg@w3.org; Mon, 30 Mar 2015 13:57:55 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1427723849; l=2897; s=domk; d=zinks.de; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:References: Subject:To:MIME-Version:From:Date; bh=Lyvg1BG+ElQAEQN2CVmdq6cP0qM+Osz2NH9qG6qDON8=; b=FLMlhbqjLmmpZKPWmn6rcylJy6SxlNETpQfobMtZErsEoAVSeyt92Biorcx6u/oO1at /AuiXxFGYrblPcyHwhj3FgPwEh/edCZL4+160XGFYNHs+lMgpZhBePubEkoeuTj/4D/7S 82J8fwT46ONbNfMAdqHB2dXlk4nlgDhKgyM=
X-RZG-AUTH: :PmMIdE6sW+WWP9q/oR3Lt+I+9KAK33vRJaCwLQNJU2mlIkBC0t1G+0bSVECAiLyE3y/RHp/qt3BsA9Yuo1YqbQw1VQ==
X-RZG-CLASS-ID: mo00
Received: from [IPv6:2001:4dd0:ff67:0:593d:7e74:b4b7:67c0] ([2001:4dd0:ff67:0:593d:7e74:b4b7:67c0]) by smtp.strato.de (RZmta 37.4 AUTH) with ESMTPSA id w02056r2UDvTSj0 (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256)) (Client did not present a certificate) for <ietf-http-wg@w3.org>; Mon, 30 Mar 2015 15:57:29 +0200 (CEST)
Message-ID: <5519564D.9050309@zinks.de>
Date: Mon, 30 Mar 2015 15:57:33 +0200
From: Roland Zink <roland@zinks.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: ietf-http-wg@w3.org
References: <em10bd3b39-e16a-4627-b277-b3cd147f81fe@bodybag>
In-Reply-To: <em10bd3b39-e16a-4627-b277-b3cd147f81fe@bodybag>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Received-SPF: none client-ip=81.169.146.220; envelope-from=roland@zinks.de; helo=mo4-p00-ob.smtp.rzone.de
X-W3C-Hub-Spam-Status: No, score=-5.5
X-W3C-Hub-Spam-Report: AWL=-1.496, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, W3C_AA=-1, W3C_WL=-1
X-W3C-Scan-Sig: lisa.w3.org 1YcaCO-0003ok-OD 863358ce2a26841856ccd5a235d0c891
X-Original-To: ietf-http-wg@w3.org
Subject: Re: 2 questions
Archived-At: <http://www.w3.org/mid/5519564D.9050309@zinks.de>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/29074
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
On 30.03.2015 14:29, Adrien de Croy wrote: > > well from where I stand there is a certain amount of duress being > applied to move people to TLS. > > * browser vendors saying they won't support plaintext (I wonder how > long that will last) me too as this doesn't seem to be much effort > * not really much effort going into working through issues with > plaintext version since it's always supposedly assumed that it won't > really be used and people will stick with 1.1 or go to https, and > issues will be solved. Somehow. Maybe. Hopefully. It is easier to upgrade to an http2 capable server than to switch to https. So I would prefer to see plaintext http2 as well. > > not many other options have been seriously considered for solving the > presumed problem of bad things happening on port 80. Like moving to > another port. 100 is still available. From a network perspective this seems to logical thing to do. A different port probably means a different URL scheme (http2 lovely), but this then shows ossification at the content provider side (not the usual middle box claim), so I guess this will not fly. > > It is reasonable to want to avoid bad things but there are other ways > than TLS, but thanks to the push to https everywhere now everyone has > a MITM that will probably make port 443 just as broken as port 80. > Maybe not quite, since I guess ISPs are less likely to do that. But > still a lot worse now than 2 years ago. TLS is not end to end. It is well adjusted to the content provider side which could choose where to terminate TLS and can throw in any number of third parties which even gets delivered the original URL through the referer header. Servers can impersonate any number of identities and get hints how to cheat (SNI). The user on the other side has no choice, she doesn't get notified about the third parties and can't deploy any infrastructure to protect her. > > Not to mention the concerns around moving en masse to TLS and what > that will do for the security of TLS itself. I'm not sure it's ready > for the load. CA compromises will affect a lot more sites. They do > happen and will continue to do so, especially as the bounty goes up by > a few orders of magnitude. A lot of eggs going into not many (CA) > baskets. > Giving the Internet to a small number of CAs seems also to be risky. If they don't like your opinion they can just revoke your certificate. Currently you can just get a different certificate from somebody else but for example with key pinning this may become more difficult. Encryption costs energy. I heard different numbers and the numbers seem to go down over the years but fighting against global warming seems not to be an IETF goal. In my opinion the discussion about using http2 and TLS should be separate and luckily http2 has both cleartext and TLS. Regards, Roland
- 2 questions Glen
- Re: 2 questions Yoav Nir
- Re: 2 questions Cory Benfield
- Re: 2 questions Constantine A. Murenin
- Re: 2 questions Matthew Kerwin
- Re: 2 questions Walter H.
- Re: 2 questions Walter H.
- RE: 2 questions Mike Bishop
- Re: 2 questions Adrien de Croy
- Re: 2 questions Cory Benfield
- Re: 2 questions Amos Jeffries
- Re: 2 questions Amos Jeffries
- Re: 2 questions Cory Benfield
- Re: 2 questions Adrien de Croy
- Re: 2 questions Yoav Nir
- Re: 2 questions Roland Zink
- Re: 2 questions Martin Thomson
- Re: 2 questions Walter H.
- Re: 2 questions Walter H.
- Re: [Moderator Action] 2 questions Glen
- Re: 2 questions Dan Anderson
- Re: 2 questions Adrien de Croy
- RE: 2 questions Xiaoyin Liu
- Re: 2 questions Adrien de Croy
- Re: 2 questions Stephen Farrell
- comprehensive TLS is not the solution, it's a bug… Walter H.
- Re: comprehensive TLS is not the solution, it's a… Walter H.
- Re: 2 questions Eric J. Bowman
- Re: comprehensive TLS is not the solution, it's a… Amos Jeffries
- Re: comprehensive TLS is not the solution, it's a… Willy Tarreau
- Re: comprehensive TLS is not the solution, it's a… Walter H.
- Re: comprehensive TLS is not the solution, it's a… Walter H.
- Re: comprehensive TLS is not the solution, it's a… Willy Tarreau
- Re: comprehensive TLS is not the solution, it's a… Maxthon Chan
- Re: comprehensive TLS is not the solution, it's a… Roberto Peon
- Re: comprehensive TLS is not the solution, it's a… Walter H.
- Re: comprehensive TLS is not the solution, it's a… Maxthon Chan
- Re: comprehensive TLS is not the solution, it's a… Willy Tarreau
- Re: comprehensive TLS is not the solution, it's a… Maxthon Chan
- Re: 2 questions Adrien de Croy
- Re: 2 questions Stephen Farrell
- Re: comprehensive TLS is not the solution, it's a… Matthew Kerwin
- Re: comprehensive TLS is not the solution, it's a… Maxthon Chan
- Re: 2 questions Maxthon Chan
- RE: comprehensive TLS is not the solution, it's a… Mike Bishop
- Re: 2 questions Poul-Henning Kamp
- Re: comprehensive TLS is not the solution, it's a… ChanMaxthon
- Re: 2 questions Stephen Farrell
- Re: 2 questions Poul-Henning Kamp
- Re: 2 questions Stephen Farrell
- Re: comprehensive TLS is not the solution, it's a… Amos Jeffries
- Re: comprehensive TLS is not the solution, it's a… Amos Jeffries
- Re: 2 questions ChanMaxthon
- Re: 2 questions Amos Jeffries
- Re: 2 questions Yoav Nir
- Re: 2 questions Poul-Henning Kamp
- Re: 2 questions Maxthon Chan
- Re: 2 questions Simpson, Robby (GE Energy Management)
- Re: 2 questions Ted Hardie
- Re: 2 questions Jason T. Greene
- Re: 2 questions Benjamin Carlyle
- Re: 2 questions Martin Thomson
- Re: 2 questions OSCAR GONZALEZ DE DIOS
- Re: 2 questions Martin Thomson
- Re: 2 questions ChanMaxthon
- Re: 2 questions Glen
- Re: 2 questions Roland Zink
- Re: 2 questions Ilari Liusvaara
- Re: 2 questions Glen
- Re: 2 questions Jim Manico
- Re: 2 questions Yoav Nir
- Re: 2 questions Glen
- Re: 2 questions Glen
- Re: 2 questions Jim Manico
- Re: 2 questions Amos Jeffries
- Re: 2 questions Maxthon Chan
- Re: 2 questions Glen
- Re: 2 questions Glen
- Re: 2 questions Ilari Liusvaara
- Re: 2 questions Amos Jeffries
- Re: 2 questions Martin Thomson
- Re: 2 questions Yoav Nir
- Re: 2 questions Martin Thomson